Skip to main content
Risk Level: High

OpenClaw Security: 7 Risks of Self-Hosting

135,000+ OpenClaw instances are exposed on the public internet right now. CVE-2026-25253 enables zero-click remote code execution. 341 malicious ClawHub skills have stolen data from 9,000+ users. Here is every risk — and what managed hosting fixes automatically.

135,000+

OpenClaw instances exposed on the public internet

341

Malicious ClawHub skills actively stealing API keys

CVSS 9.8

CVE-2026-25253 — zero-click RCE, all versions before 2026.2.1

The 7 security risks of self-hosting OpenClaw

Each risk includes the exact GetClaw fix applied automatically on every managed gateway.

1

Exposed gateway port

Critical

Default OpenClaw listens on 0.0.0.0:3000. Any misconfigured firewall leaves your gateway publicly reachable — no authentication required.

GetClaw fix

Gateway bound to localhost only, Caddy reverse proxy with TLS enforced on every request.

2

CVE-2026-25253 zero-click RCE

Critical

Affects all OpenClaw versions before 2026.2.1. Attackers can execute arbitrary code via a crafted message to an exposed gateway. CVSS score: 9.8.

GetClaw fix

Patches applied within 24 hours of release, tested in staging before rolling to production.

3

Malicious ClawHub skills

High

341 skills on ClawHub actively steal API keys and user data. 13.4% of the 13,700+ skill catalogue has critical security issues per Snyk audit.

GetClaw fix

Curated skill allowlist — only audited, vetted skills are available on your gateway.

4

API key exposure

High

Self-hosted OpenClaw stores API keys in plaintext config files on disk. One file-read vulnerability or backup leak exposes every key you've configured.

GetClaw fix

All keys stored in an encrypted Vault, never written to disk in plaintext, injected at runtime only.

5

No automatic security updates

High

Self-hosters must manually monitor for CVEs and apply patches. The average time from CVE disclosure to patch on self-hosted instances is 23 days.

GetClaw fix

Automatic patching within 24 hours of CVE disclosure — zero manual intervention required.

6

Runaway API billing loops

Medium

Misconfigured agents can enter infinite retry loops, accumulating $200/day or more in API costs overnight with no built-in circuit breaker.

GetClaw fix

Per-session token budget, daily spend caps, and loop detection — agent pauses automatically when limits are reached.

7

No audit trail

Medium

Self-hosted OpenClaw has no built-in logging of what your agent accessed, modified, or sent. You cannot investigate an incident after the fact.

GetClaw fix

Full agent action log with tamper-proof timestamps on every plan — every tool call recorded.

Self-hosted vs GetClaw Hosting

Security posture comparison — out of the box, no configuration required.

Security feature Self-hosted OpenClaw GetClaw Hosting
Gateway exposure Public port (risk by default) localhost only — never publicly reachable ✓
CVE patching Manual — average 23 days Automatic within 24 hrs of disclosure ✓
ClawHub skills All 13,700+ skills, unvetted Curated allowlist — audited skills only ✓
API key storage Plaintext config file on disk Encrypted Vault — never written to disk ✓
Spend protection None — unlimited runaway risk Daily caps + loop detection ✓
Audit log None Full tamper-proof agent action log ✓

Frequently asked questions

Is OpenClaw safe to use?
OpenClaw is safe when properly configured, but self-hosting requires security expertise. The default installation exposes your gateway on a public port, stores API keys in plaintext, and does not enforce authentication. GetClaw Hosting applies hardened defaults automatically.
What is CVE-2026-25253?
CVE-2026-25253 is a critical zero-click remote code execution vulnerability in OpenClaw versions before 2026.2.1. An attacker can execute arbitrary code by sending a crafted message to an exposed OpenClaw gateway. GetClaw automatically patched all managed instances within 6 hours of disclosure.
Are ClawHub skills safe to install?
A Snyk security audit found 13.4% of ClawHub's 13,700+ skills have critical security issues. 341 skills were found actively stealing user API keys. GetClaw maintains a curated allowlist of audited skills only.
How does GetClaw protect my API keys?
GetClaw stores all API keys in an encrypted Vault. Keys are never written to disk in plaintext and are injected at runtime only. Even if the server were compromised, API keys cannot be extracted from disk.

Run OpenClaw without the security risk

Hardened defaults, automatic patching, encrypted key vault — applied from day one on every plan starting at $29/mo.